API keys
Create, store and revoke the API keys that let your code use the Nisuform API, and what each key is allowed to do.
An API key lets your code use the Nisuform API as you, in one of your teams.
Create a key
- Open Account from the menu under your picture.
- In API keys, choose Create key.
- Give it a name you'll recognize later, like
Production serverorZapier. - If you belong to more than one team, pick the team the key works in.
- Choose Create key and copy it.
The key is shown once. Nisuform only stores a hash of it, so nobody can show it to you again. If you lose it, revoke it and create a new one.
Keys start with nfa_. The dashboard shows the first 12 characters of each key so you can tell them apart.
Keep keys secret
Anyone who has a key can read, change and delete the forms and submissions in its team.
- Store it in an environment variable or a secret manager, like
NISUFORM_API_KEY. - Use it only on servers and in scripts. Never put it in website code, a mobile app or a public repository.
- Create one key per app or server, so you can revoke one without touching the others.
A form key and an API key are different things:
| Form key | API key | |
|---|---|---|
| Looks like | k3yz8q2m4n6p0r5t7v9w | nfa_ and 40 more characters |
| Used in | Your form's endpoint, /s/{key} | The Authorization header of API requests |
| Public | Yes, it is in your website's code | No, keep it secret |
| Can | Send submissions to one form | Manage every form and submission in a team |
What a key can do
A key can use the account, forms and submissions endpoints in its team, including deleting forms and submissions.
It can't:
- manage teams, members or invites,
- change billing or plans,
- connect, change or test integrations,
- read analytics,
- create, list or revoke API keys,
- change your profile or delete your account.
Those stay in the dashboard, where you are signed in.
Keys and teams
A key works in the team you picked when you created it, no matter which team is open in the dashboard.
- If you leave a team or are removed from it, your keys for that team are deleted and stop working.
- If a team is deleted, every key for it is deleted too.
- If you delete your account, all your keys are deleted.
To use the API in two teams, create a key in each.
Revoke a key
In Account, find the key under API keys and choose Revoke. It stops working right away, and requests that use it get 401.
Revoke a key as soon as you think someone else has seen it.
Last used
Each key shows when it was last used, which helps you find keys that nothing uses anymore. The time is updated at most once an hour, so a key that is in use can show a time up to an hour old.
Limits
| Limit | Value |
|---|---|
| Keys per account | 25 |
| Requests per key | 120 a minute |
| Key name | 100 characters |